fix(10.1): WR-03 walk the whole partial view model before rendering
refusedViewModel compared only the top-level type with the controller's model. It now walks the type through pointers, slices, arrays, maps, struct fields and the results of exported methods, and the values held in interface-typed members, refusing the controller's model, any other GORM model (TableName, a gorm tag, gorm.Model, gorm.DeletedAt) and html/template's trusted content types anywhere in that structure.
This commit is contained in:
@@ -187,8 +187,9 @@ type HasAdminActions interface {
|
||||
// renders (config_list.yaml headerPartial, fields.yaml `type: partial`). name
|
||||
// is the partial name; record is the scoped record for a form partial on an
|
||||
// existing record, else nil. The result must be a curated view model built
|
||||
// for the template, never the GORM model itself: the framework refuses a
|
||||
// value of the controller's model type.
|
||||
// for the template, never a GORM model: the framework refuses a view model
|
||||
// that carries the controller's model or any other GORM model, even nested
|
||||
// in a field, a collection or an interface value.
|
||||
type AdminPartialData interface {
|
||||
PartialData(ctx context.Context, name string, record any) (any, error)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user